{"id":"GHSA-mpwp-4h2m-765c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mpwp-4h2m-765c","summary":"Active Job - Object injection security vulnerability","details":"Active Job vulnerability: An Active Job bug allowed String arguments to be deserialized as if they were Global IDs, an object injection security vulnerability.","published":"2026-01-16T19:21:54Z","modified":"2026-02-03T02:56:31.524961Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"activejob","fixedVersion":"4.2.0.beta2"}],"fix":null,"references":[{"type":"WEB","url":"https://advisories.gitlab.com/pkg/gem/activejob/OSVDB-112347"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activejob/GHSA-mpwp-4h2m-765c.yml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activejob/OSVDB-112347.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T02:56:31.524961Z"}}